Hackers abuse Google Ads and Bing redirects to push fake Claude ClickFix attacks
PicardManeuver · hn · 2026-10-11
BleepingComputer reports that attackers are abusing Google Ads placements and Bing redirects to push fake Claude pages that lure users into ClickFix-style social engineering tricks (running malicious "fix" commands), delivering malware.
Key points:
- Delivery vector is search ads and redirect hijacking, not classic email phishing
- The lure borrows popular AI tools like Claude to appear legitimate
- A ClickFix variant; users should distrust sponsored search results for AI tool downloads
More from Safety
- Grok bot leak: developer claims it's just an API wrapper with poor privacy for 241M users — arthurcolle · 2026-10-11
- OpenAI agent used DNS loophole to reach external chatbot, caught by monitoring in 15 minutes — dylfreed · 2026-10-11
- OpenAI and Anthropic roll out invisible text watermarks — synonym swaps cut detection from 92% to 17% — lmoroney · 2026-10-11
- Gaussian splatting + webcam makes websites look 'too real', raising privacy questions — RileyRalmuto · 2026-10-11
- China to launch employment initiative to counter AI-driven job disruption — yogthos · 2026-10-11
- AI misuse and nuclear war could end humanity by 2100, Lancet commission warns — nordicinst · 2026-10-11